{"id":"openSUSE-SU-2026:21615-1","summary":"Security update for weechat","details":"This update for weechat fixes the following issues:\n\nChanges in weechat:\n\n- Update to 4.10.0:\n\n  Added\n  * core: add command /theme (#1338)\n  * core: add built-in \"light\" theme, applied automatically on first\n    start on light-background terminals (#1338)\n  * core: add themable flag on configuration options (#1338)\n  * core: add options weechat.look.theme and\n    weechat.look.theme_backup (#1338)\n  * api: add function theme_register (#1338)\n  * fset: add filter t:themable (#1338)\n  * relay/api: add resource GET /api/scripts\n  * relay: add option relay.network.unix_socket_permissions (#2317)\n  * script: add info \"script_languages\"\n\n  Changed\n  * core: improve speed of /upgrade with a lot of buffers and lines\n    (#2338, #2339, #2341)\n  * core: improve speed of display of long words in chat area (#2336)\n  * core: add condition on connected relay api clients in default\n    value of option weechat.look.hotlist_add_conditions\n  * core: add /mute in default command for key Alt+= (toggle filters)\n  * api: change type of parameter \"pos_option_name\" to \"const char **\"\n    in function config_search_with_string\n  * relay/api: add field \"last_read_line_id\" in GET /api/buffers\n\n  Fixed\n  * core: fix infinite loop when option weechat.look.read_marker_string\n    is set to a string with a width of zero (#2337)\n  * core: fix option weechat.look.color_real_white not applied when\n    color is \"white\" on 16+ colors terminals (#1742)\n  * core: fix buffer overflow in connection to SOCKS5 proxy (#2325)\n  * api: fix infinite loop in function string_replace when the search\n    string is empty\n  * api: do not free dynamic string on error in function string_dyn_concat\n  * irc: fix tag in message with list of names when joining a channel\n  * fset: remove error displayed in core buffer when clicking with the\n    mouse below the last option displayed\n  * guile, lua, perl, python, ruby, tcl: fix conversion of dates in\n    the API functions\n  * irc: fix conversion of dates in received messages\n\n  Security\n  * core: fix buffer overflow in display of time in chat area with a\n    custom time format (#2342)\n  * core: fix integer overflow in size calculation when evaluating\n    \"${hide:...}\" and \"${base_encode:...}\" (#2335)\n  * core: fix possible buffer overflow in command /color alias (#2330)\n  * core: fix possible buffer overflow in list of commands displayed\n    by /help (#2330)\n  * irc: fix heap use-after-free when a batched message causes a\n    disconnection from the server (GHSA-rfmh-3r7f-jpx5)\n  * irc: fix stack buffer overflow when splitting a JOIN message\n    with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)\n  * irc: limit size of data received from the server to prevent\n    memory exhaustion\n  * irc: fix out-of-bounds read on incoming DCC command with a\n    quoted filename ending the message (#2322)\n  * logger: fix path traversal in log file name when a buffer local\n    variable contains the char used internally to protect directory\n    separators (#2340)\n  * relay: fix use-after-free and double free on remote buffer\n    (GHSA-hx59-4hq9-6vmw)\n  * relay: fix authentication bypass with the \"plain\" password hash\n    algorithm (GHSA-68ff-gq39-pqjm)\n  * relay: limit size of decompressed websocket frame with\n    permessage-deflate to prevent memory exhaustion\n    (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)\n  * relay: limit size of received websocket frame and HTTP body to\n    prevent memory exhaustion\n  * relay: limit size of partial message received while reading an\n    HTTP request to prevent memory exhaustion\n  * relay: fix timing attack on password authentication\n    (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)\n  * relay: fix out-of-bounds read in dump of data (#2324)\n  * relay/api: fix memory leak in resources \"handshake\", \"input\" and\n    \"completion\" (GHSA-wmpc-m6g9-fwj8)\n  * relay: fix read of uncompressed websocket frame (#2331)\n  * api, relay: fix timing attack on TOTP validation\n    (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)\n  * xfer: replace directory separator in remote nick by underscore\n    in download filename to prevent writing the file outside the\n    download directory (#2321)\n  * xfer: fix out-of-bounds read when receiving empty line in DCC\n    chat (#2323)\n  * xfer: fix out-of-bounds write in xfer file transfer resume (#2326)\n\n- Update to 4.9.5:\n  * core: fix buffer overflow in display of time in chat area with a\n    custom time format (#2342)\n  * irc: fix heap use-after-free when a batched message causes a\n    disconnection from the server (GHSA-rfmh-3r7f-jpx5)\n  * irc: fix stack buffer overflow when splitting a JOIN message with\n    a large list of channels and keys (GHSA-q2xg-9ggx-77mr)\n  * relay: fix use-after-free and double free on remote buffer\n    (GHSA-hx59-4hq9-6vmw)\n  * relay: increase max size for decompressed websocket frame\n\n- Update to 4.9.4:\n\n  Changed\n  * core: improve speed of display of long words in chat area (#2336)\n\n  Fixed\n  * core: fix infinite loop when option weechat.look.read_marker_string\n    is set to a string with a width of zero (#2337)\n  * core: fix integer overflow in size calculation when evaluating\n    \"${hide:...}\" and \"${base_encode:...}\" (#2335)\n  * logger: fix path traversal in log file name when a buffer local\n    variable contains the char used internally to protect directory\n    separators (#2340)\n  * relay: fix authentication bypass with the \"plain\" password hash\n    algorithm (GHSA-68ff-gq39-pqjm)\n\n- Update to 4.9.3:\n  * core: fix buffer overflow in connection to SOCKS5 proxy (#2325)\n  * core: fix possible buffer overflow in command /color alias (#2330)\n  * core: fix possible buffer overflow in list of commands displayed\n    by /help (#2330)\n  * api: do not free dynamic string on error in function string_dyn_concat\n  * relay/api: fix memory leak in resources \"handshake\", \"input\" and\n    \"completion\" (GHSA-wmpc-m6g9-fwj8)\n  * relay: fix read of uncompressed websocket frame (#2331)\n  * xfer: fix out-of-bounds write in xfer file transfer resume (#2326)\n\n- Update to 4.9.2:\n  * api: fix infinite loop in function string_replace when the search\n    string is empty\n  * irc: limit size of data received from the server to prevent\n    memory exhaustion\n  * irc: fix out-of-bounds read on incoming DCC command with a quoted\n    filename ending the message (#2322)\n  * relay: limit size of received websocket frame and HTTP body to\n    prevent memory exhaustion\n  * relay: limit size of partial message received while reading an\n    HTTP request to prevent memory exhaustion\n  * relay: fix out-of-bounds read in dump of data (#2324)\n  * xfer: replace directory separator in remote nick by underscore in\n    download filename to prevent writing the file outside the download\n    directory (#2321)\n  * xfer: fix out-of-bounds read when receiving empty line in DCC\n    chat (#2323)\n\n-  Update to 4.9.1:\n   * core: fix option weechat.look.color_real_white not applied when\n     color is \"white\" on 16+ colors terminals (#1742)\n   * irc: fix tag in message with list of names when joining a channel\n   * relay: limit size of decompressed websocket frame with\n     permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)\n   * relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)\n   * api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)\n\n- Update to 4.9.0:\n\n  Added\n  * typing: add option typing.look.item_text (#2305)\n\n  Fixed\n  * core: fix crash with /eval when the current buffer is closed in a\n    command\n  * core: fix buffer size in function util_parse_time, causing buffer\n    overflow error in unit tests\n  * irc: fix display of CTCP query sent multiple times to the same\n    user when capability echo-message is enabled (#2309)\n  * irc: fix unit of server option anti_flood from seconds to\n    milliseconds in output of /server listfull\n  * irc: fix creation of irc.msgbuffer option without a server name\n  * irc: ignore self join if the channel is already joined (#2291)\n  * relay/api: fix memory leaks in resources \"ping\" and \"sync\"\n  * relay/api: fix memory leak in receive of message from remote WeeChat\n\n- Update to 4.8.2:\n  * irc: ignore self join if the channel is already joined (#2291)\n  * relay/api: fix memory leaks in resources \"ping\" and \"sync\"\n  * relay/api: fix memory leak in receive of message from remote WeeChat\n\n- Update to 4.8.1:\n  * core: fix buffer size in function util_parse_time, causing buffer\n    overflow error in unit tests\n  * irc: fix creation of irc.msgbuffer option without a server name\n\n- Update to 4.8.0:\n\n  Removed\n  * irc: remove temporary servers and option irc.look.temporary_servers\n\n  Changed\n  * api: add support of date like ISO 8601 but with spaces and lower\n    t and z in function util_parse_time (#886)\n  * irc: request and perform SASL authentication when the server\n    advertises SASL support with message \"CAP NEW\" (#2277)\n  * irc: send SASL username with mechanism EXTERNAL (#2270)\n  * logger: change default time format to %@%F %T.%fZ (UTC) (#886)\n  * logger: use function util_parse_time to parse date/time in log\n    files (#886)\n  * relay/api: return an error 400 (Bad Request) when URL parameters\n    \"colors\", \"nicks\", \"lines\" and \"lines_free\" have an invalid value\n  * relay/api: return an error 401 (Unauthorized) when header\n    \"x-weechat-totp\" has an invalid value\n  * xfer: add buffer local variable \"server\" in DCC CHAT buffers\n  * core, irc, relay: add tag \"tls\" in gnutls messages\n  * irc: add tags \"irc_cap\" and \"log3\" in client capability request\n    and SASL not supported messages\n  * build: require Curl ≥ 7.68.0 (#2268)\n  * build: require GnuTLS ≥ 3.6.3 (#2268)\n  * build: require libgcrypt ≥ 1.8.0 (#2268)\n  * build: require Enchant v2 (#2268)\n  * build: require Lua ≥ 5.3 (#2268)\n\n  Added\n  * core: add option weechat.completion.cycle\n  * core: add hdata for hooks\n  * api: add functions util_parse_int, util_parse_long and\n    util_parse_longlong\n  * buflist: add variable ${index_displayed}\n\n  Fixed\n  * core: display an error message in case of invalid parameters in\n    commands /bar, /buffer, /cursor, /print and /window\n  * api: fix file descriptor leak in hook_url when a timeout occurs\n    or if the hook is removed during the transfer (#2284)\n  * api: fix parsing of date/times with timezone offset in function\n    util_parse_time\n  * irc: fix warning on creation of irc.msgbuffer option when the\n    server name contains upper case letters (#2281)\n  * irc: display a warning for each unknown or invalid server option\n    in commands /connect and /server\n  * irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and\n    MODE (#2286)\n  * irc: fix reset of color when multiple modes are set with\n    command /mode\n  * relay/api: fix crash when an invalid HTTP request is received\n    from a client\n  * relay/api: return HTTP error 404 instead of 400 when the buffer\n    is not found in resources completion and input\n  * relay/api: return HTTP error 400 in case of invalid body in\n    resource ping\n","modified":"2026-08-23T18:23:37.659655553Z","published":"2026-08-20T16:20:15Z","related":["CVE-2026-53524","CVE-2026-53525"],"upstream":["CVE-2026-53524","CVE-2026-53525"],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53525"}],"affected":[{"package":{"name":"weechat","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/weechat&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.10.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"weechat-python":"4.10.0-bp160.1.1","weechat-perl":"4.10.0-bp160.1.1","weechat-devel":"4.10.0-bp160.1.1","weechat":"4.10.0-bp160.1.1","weechat-lua":"4.10.0-bp160.1.1","weechat-tcl":"4.10.0-bp160.1.1","weechat-lang":"4.10.0-bp160.1.1","weechat-ruby":"4.10.0-bp160.1.1","weechat-spell":"4.10.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21615-1.json"}}],"schema_version":"1.9.0"}